41 ms·
The xz sshd backdoor rabbithole goes quite a bit deeper
- MBCook 2y agoLuckily, thanks to Elon, we’ll never know since you haven’t have a Twitter account to view the thread.
- mkl 2y agoChange "twitter" to "twiiit" to get a random nitter instance: https://twiiit.com/bl4sty/status/1776691497506623562 https://twiiit.com/bl4sty/status/1776691497506623562
- ethanwillis 2y agoNo thanks, I support an open web.
- beepbooptheory 2y agoYou support the open web by stealing from the closed one!
- Rodeoclash 2y agoI'm glad you get it!
- int_19h 2y agoHack the planet!
- mkl 2y agoIgnoring the closed web is not the same as supporting the open web. I support whatever mirrors and tools get closed knowledge into the open. (Edited to remove snark.)
- ethanwillis 2y agoAnd yet a short time later: "Instance has been rate limited. Use another instance or try again later."
- kibwen 2y ago> Choosing ignorance over knowledge If there's some piece of knowledge that's absolutely, positively critical to my life, it will exist somewhere that actually matters, not on Twitter.
- mkl 2y agoSure, but almost no knowledge that is interesting, valuable, useful, etc., is absolutely, positively critical to your life. Almost nothing on HN has that level of importance, but you are here learning interesting things, and unfortunately the first place some of those things appear is still Twitter.
- k8svet 2y agoWhere does it end, fellow person? What is going to be the excuse/defense/workaround whenever Nitter instances are completely suffocated? Just suck it up and sign up so you can continue to participate on a increasingly hostile, toxic, manipulated platform in service of a narcasists deranged ego? Because Joe Bob Expert is too lazy to post elsewhere? No, I'm sorry, but when is enough, enough? I know I'm missing out on good content, and I don't care. I have _some_ self-respect.
- k8svet 2y agoI don't even know if that's true, but I don't care. Twitter, at this point, is far more egregious than reddit, and I swore months ago I'd never contribute there. It blows my mind that people still play in Elon's piss-filled sandbox because they love the dopamine hits of bot-inflated engagement metrics. Yes, you casual reader that keeps posting on Twitter due to laziness and momemtum, I'm absolutely talking about you. Your laziness is hurting everyone. And I'm not alone, you're limiting your audience and prioritizing, well, people too lazy to get off Twitter, and ignoring the technical, prescient (observant, at this point?), informed crowd that have left for elsehwhere. /shrug
- MBCook 2y agoThe really stupid thing is you have to know you’re missing stuff. If you’re sent a random link you can’t tell if it’s a one-off or a 45 tweet thread. It looks open but it’s clearly not.
- jxyxfinite 2y agoI thought nitter was officially dead. Nice to see some instances are still working
- justinclift 2y agoOh. Nitter didn't stop working a few weeks ago after all? Oops, now that's giving: Instance has been rate limited. Use another instance or try again later. So maybe "kind of working" is the better description. :)
- opello 2y agoAren't all the nitter instances going to die with the anonymous guest account restrictions? I've not closely followed those developments.
- publius_0xf3 2y agoWow, it works. But it's not random, afaict. I keep getting the privacydev instance. How do they keep theirs up and running?
- avalys 2y agoHow much does a Twitter account cost?
- GaggiX 2y agoProbably a bit of mental health.
- defrost 2y agoDignity ...
- ethanwillis 2y agoYour personal information.
- Brian_K_White 2y agoapproximately twice as many principles as it's worth
- joshmanders 2y ago[flagged]
- aaron695 2y ago[dead]
- deleted 2y ago[deleted]
- wilkystyle 2y agohttps://threadreaderapp.com/thread/1776691497506623562.html https://threadreaderapp.com/thread/1776691497506623562.html
- deleted 2y ago[deleted]
- atomicnumber3 2y agoThe sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."
- dboreham 2y ago> And it all got caught because of a fairly obvious perf regression Always possible that was "parallel construction" evidence. Someone at a TLA discovered the attack by some other means, had a quiet Signal chat with a former colleague who works at MS...
- paleotrope 2y agoInteresting possibilty but it seems like the "discovery" story is too complex and unbelievable.
- eli 2y agoThere doesn’t seem to be any evidence to support this whatsoever yet it’s nearly impossible to disprove. Classic conspiracy theory.
- account42 2y agoThere also isn't really a reason for some contrived parallel construction here - whoever found the issue could just point to it without explaining how it was detected. They could even do that anonymously. > Classic conspiracy theory. I would not be too quick to shit on "conspiracy theories" however as there are plenty of proven cases of people conspiring against the interests of the public.
- GrantMoyer 2y agoIt seems like a much more suitable parallel construction story to invent in this instance would be something like "there were valgrind issues reported, but I couldn't reproduce them, so I sanity checked the tarball was the same as the git source. It wasn't."
- goalieca 2y agoThis is fantastic. Great work actually triggering the bug!
- TibbityFlanders 2y ago[dead]
- deleted 2y ago[deleted]
- ufmace 2y agoThe weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and obfuscation techniques used. Yet also a bit amateur-ish in the bugs and performance regressions that slipped out into production versions. I'm not saying it's amateur-ish to have bugs. I'm saying, if this was developed by a highly competent state-sponsored organization, you'd think they would have developed the actual exploit and tested it heavily behind closed doors, fixing all of the bugs and ensuring there were no suspicion-creating performance regressions before any of it was submitted into a public project. If there was no performance regression, much higher chance this never would have been discovered at all.
- darkclouds 2y ago[dead]
- braiamp 2y agoThere are thousands of ways that performance can be impacted. No matter how good you are at developing, there will be a workload that would have a performance hit. Phoronix has been several times reporting issues to the Linux kernel because performance regression with their test suite. Performance tests tend to take more time than correctness tests.
- ufmace 2y agoNot seeing that as a point. It's probably not possible to have no performance hit whatsoever when you're checking the exact nanosecond count of every little thing. But usually nobody is doing that. It shouldn't be hard to not cause a substantial enough performance regression in SSHD logins that somebody who wasn't already monitoring that would notice and decide to dig into what's going on. I'm not sure if it's been revealed yet what this thing actually does, but it seems like all it really needs to do is to check for some kind of special token in the auth request or check against another keypair.
- hakdbha 2y ago[dead]
- bilekas 2y agoWithout having a Twitter account I have a really hard time following these threads. Is there some write up? Edit : Check comments. Yes, the backdoor hasn't been decompiled/reverse engineered yet. But it feels like clickbait to say : "It goes deeper"... Obviously. Nobody knows what it fully does yet. There was no assumption of knowing what it did.
- aeyes 2y agoShort summary is that it allows auth bypass, not just RCE.
- bilekas 2y agoYes, I understand.. It's just not a surprise.
- ckcheng 2y agoIt was surprising because previously we had: 'XZ backdoor: "It's RCE, not auth bypass, and gated/unreplayable."' [0]. [0]: https://news.ycombinator.com/item?id=39877267 https://news.ycombinator.com/item?id=39877267 (811 comments)
- bilekas 2y agoDid you understand the XZ backdoor before the rest of us ? We will figure it out. With all of our stubborn ways, we can document it. Clap
- mr_mitm 2y agoRCE as root is already the worst case though. The auth bypass is basically just a convenience feature of the backdoor. So yeah it's mildly interesting but not really a new development of the story.
- deleted 2y ago[deleted]
- koreanguy 2y ago[dead]
- sylware 2y ago[flagged]
- DustinBrett 2y agoIt's as if it's not going away...
- EvanAnderson 2y agoHas anybody done a writeup of the obfuscation in the backdoor itself (not the build script that installs it)? I threw the binary into Ghidra and looked thru the functions it found, but having no familiarity with the ifunc mechanism it uses to intercept execution I have up and set it aside for others. I'd have to assume since there's anti-debug functionality that the code is also obfuscated. Since it shipped as an opaque binary I assumed at least some of the code would be encrypted with keys we don't have (similar to parts of the STUXNET payload).
- bilekas 2y agoNo full dissemination of the backdoor itself has been done yet, as for the anti-debug, sure you can avoid things like that with flags. But this was done at compile level so its a bit more tricky. > I'd have to assume since there's anti-debug functionality that the code is also obfuscated. Not really, as above it was done at build time.. So you have already set your home up. It's shown the problems with package managers not taking source from the right place.
- EvanAnderson 2y agoSo ifunc is a link-time thing and not a runtime thing, then? (My background, when it comes to linking, is DOS and Windows.)
- asveikau 2y agoIt's runtime, but I think dynamic linker. The Windows equivalent would be if a library patched some code at dllmain. Actually the Detours library in the Windows world is similar. But it's for performance; the idea is you would patch some function references based on the CPU revision to get faster code specific to your CPU.
- bilekas 2y agoThis is a really nice windows analogy, however it goes without saying this package wasn't aiming for Windows, ironically, it chose the path (as we seen so far) of least resistance. If you're hooked to an sshd service, your golden. They put 5 checks (maybe comically) in a row to make sure it was linux I this case .. who knows what's next.
- UncleOxidant 2y agoThis. Could people stop posting xitter links and post threadreaderapp links like this instead. Thank you.
- ranger_danger 2y agoHow do they get around the account/resource limits?
- scubbo 2y agoAmusing. I was always irritated by the very concept of threadreaderapp and by people's propensity for posting the links (just read it on the website! There's no need to spend extra compute to join up some divs!) - but Elon's ever-increasing breakage of the site now makes it genuinely useful.
- k8svet 2y ago"ever increasing"? Twitter is completely, 110% unusable without an account (and dear god, I dare some of you to make a new account and see what the process and default content is. It's gross). I say 110% not to be hyperbolic -- It shows you non-latest tweets on profiles, it doesn't let you see tweet threads or replies, even from the original poster when they post a chain of tweets. I literally can't read any of this content save for the threadreadapp link. ...
- jpalawaga 2y agoit's a rather good thing that this was found before it made it out broadly. Not just for obvious reason of not wanting an unknown party to have RCE on your infrastructure. I think as people keep digging they will eventually formulate a payload which will allow the backdoor to be used by anyone. As bad as it is for a single party to have access, it's much worse for any (every?) party to have access.
- justusthane 2y agoIsn’t that more or less impossible since the payload is a private RSA key?
- timschmidt 2y agoSee https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Dual_EC_DRBG for another backdoor requiring a private key, in which the key was simply replaced in a subsequent supply chain attack(!) with a key known to the attacker: "In December 2015, Juniper Networks announced[55] that some revisions of their ScreenOS firmware used Dual_EC_DRBG with the suspect P and Q points, creating a backdoor in their firewall. Originally it was supposed to use a Q point chosen by Juniper which may or may not have been generated in provably safe way. Dual_EC_DRBG was then used to seed ANSI X9.17 PRNG. This would have obfuscated the Dual_EC_DRBG output thus killing the backdoor. However, a "bug" in the code exposed the raw output of the Dual_EC_DRBG, hence compromising the security of the system. This backdoor was then backdoored itself by an unknown party which changed the Q point and some test vectors.[56][57][58] Allegations that the NSA had persistent backdoor access through Juniper firewalls had already been published in 2013 by Der Spiegel.[59] The kleptographic backdoor is an example of NSA's NOBUS policy, of having security holes that only they can exploit."
- samus 2y agoIf it is known to belong to a widely deployed backdoor that can't be patched away in time, then it is worth to recover the key by brute force using supercomputers. Of course, such capabilities are rather restricted to nation states.
- 2y ago
- noman-land 2y agoI haven't been following this story super closely but I find it extremely odd that I've heard zero discussion about the perpetrator of this hack.
- db48x 2y agoWhat’s to discuss? Nothing is known about him.
- chrismartin 2y agoThere's a lot of metadata about when/how they used git and IRC, and some preliminary analysis on same. Another surname in one of the commits. An apparent LinkedIn account. (See heading "OSINT" in https://boehs.org/node/everything-i-know-about-the-xz-backdoor https://boehs.org/node/everything-i-know-about-the-xz-backdo... .) A lot of these tracks could be intentionally manipulated by a sophisticated actor to disguise their identity, but it's not "nothing".
- db48x 2y agoLike I said, we don't know anything worth having a real discussion about. Maybe he was in the +03 time zone, and pretending to be in +08, but that's not enough to base a discussion on.
- coginthemachine 2y agoI'm concerned about the long game nature of things here. 1-Sure they bid their time to setup the "infrastructure" to create the backdoors. 2-I'm sure their plan was to play another long game after the exploit got in the wild, in production. It's the right way to spend lottery money. Invest. 3-That makes me wonder if such games are being played today. Scary.
- dvektor 2y agoSomehow nobody has mentioned this yet but big props to the original author of this post. Super impressive work
- sureglymop 2y agoDoes anyone have a good explanation or introduction into the performance testing that was done to find this? And how to get started? Actually measuring performance always seemed to be a very hard task and I'd like to be able to do similar testing as the person which found this backdoor.
- glibg10b 2y agohttps://www.openwall.com/lists/oss-security/2024/03/29/4 https://www.openwall.com/lists/oss-security/2024/03/29/4 > == Observing Impact on openssh server == > > With the backdoored liblzma installed, logins via ssh become a lot slower. > > time ssh nonexistant@...alhost > > before: > nonexistant@...alhost: Permission denied (publickey). > > before: > real 0m0.299s > user 0m0.202s > sys 0m0.006s > > after: > nonexistant@...alhost: Permission denied (publickey). > > real 0m0.807s > user 0m0.202s > sys 0m0.006s
- deleted 2y ago[deleted]
- intelVISA 2y ago> measuring performance always seemed to be a very hard task It's not hard: it's either easy, or impossible, depending on the culture at your shop. At the basic level it's trivial - you instrument code and interpret the results against the HW and lower level machine counters. Depending on $lang you have many good libraries for this kicking around, the hard part is working with a corp that values performance (99% do not) so none of the required mindset and surrounding infra will be setup to permit this in any useful capacity.
- cesarb 2y agoFrom what I understand, it wasn't even the performance testing itself that caught the backdoor. The developer wanted to have the machine as quiescent as possible (so that nothing else running on it would interfere) before starting the performance tests, but sshd was using much more CPU than expected (and this could be observed with simple tools like "top"). My guess is that the usual "backscatter" of password guessing ssh login attempts from all over the Internet normally uses very little CPU time in sshd before being rejected, but the backdoor made each login attempt use a significant amount of CPU time to check whether it was an encrypted request from the attacker (and this particular machine had its sshd open to the Internet because it was a cloud machine being accessed via ssh through the open Internet).
- m3kw9 2y agoEveryone now looking at their test data directory
- 1vuio0pswjnm7 2y agoAlternative to thereaderapp.com: https://nitter.poast.org/bl4sty/status/1776691497506623562 https://nitter.poast.org/bl4sty/status/1776691497506623562
- mattlondon 2y agoI often wonder with these sort of things, where there are lots of write-ups by geeks who dive-deep into the details, why do people say "This has to be state sponsored!", "Look at the timestamps! Irrefutable proof!" Yes this was sneaky and yes this was a "slow burn" but is there really anything in the xz case that requires more than just a single competent person? Anything that requires state-level of sponsorship? The fact that random individuals online are able to dissect it and work things out suggests that it is comprehendible by a single person. What is to say it that this was not just one smart-yet-disgruntled person acting alone?
- fliglr 2y agoThere is nothing. Nobody has any idea who he is
- fl7305 2y agoI agree. The hack took someone with a lot of skills, determination and time. But doesn't that describe a significant portion of open source developers? There is also clear motivation. Wouldn't the exploit have been worth many millions on the black market?
- lolinder 2y agoThe biggest thing for me that points to a state actor is the amount of time committed to the social engineering attack versus the expected value of the prize. A for-profit scheme built this way would be irrational, which doesn't preclude it being an irrational actor (or an individual with a motive other than profit) but does point to a state actor as a likely candidate. The total value of the prize, if successful, would be worth a lot if you could sell it, but the odds of successfully getting an exploit into major infrastructure that goes undetected for long enough for your customers to buy and use it are tiny. States can afford moonshots, but I tend to expect private individuals to seek targets with a higher expected value. Of course, that doesn't mean it was a competent state actor or that they allocated a ton of resources to it.
- fl7305 2y ago> I tend to expect private individuals to seek targets with a higher expected value. If you're a very skilled and dedicated hacker, what other targets do you have that can net you many millions of dollars? > or an individual with a motive other than profit Isn't one of the most striking things about the hacker community the extreme amounts of time and effort that are put into things that are not expected to generate any profit? I mean, there are people who spend all their free time over several decades just digging tunnels under their property. Or build a 6502 CPU from discrete transistors. Etc.
- yobid20 2y agoPlot twist: it was the NSA
- yobid20 2y agoThe NSA is downvoting me!
- Havoc 2y agoIt’s wild that days later it still hasn’t been unravelled. For something with so many global eyes on it & in theory the key pieces being available that is quite an achievement in obfuscation
- Burak545 2y ago[flagged]
- Scottwilliams 2y ago[dead]
- Scottwilliams 2y ago[dead]
- Charlie545 2y ago[dead]